But given the general security situation on Windows, it would be really nice to have, for example, the browser strongly isolated from the rest of the system.
The idea of using virtualization to enforce stronger isolation between different parts of the system seem like a good one, and it does not appear to be that non-obvious (of course, in hindsight so many things do).
https://www.bromium.com/advanced-endpoint-security/our-techn...